Hide Forgot
Envoy through 1.17.3 contains a remotely exploitable vulnerability where an HTTP request with escaped slash characters can bypass Envoy's authorization mechanisms.
Acknowledgments: Name: the Envoy security team
*** EmbargoedBug 1958384 has been marked as a duplicate of this bug. ***
This issue has been addressed in the following products: OpenShift Service Mesh 2.0 Via RHSA-2021:1538 https://access.redhat.com/errata/RHSA-2021:1538
This issue has been addressed in the following products: OpenShift Service Mesh 1.1 Via RHSA-2021:1540 https://access.redhat.com/errata/RHSA-2021:1540
Upstream fix: https://github.com/envoyproxy/envoy/commit/5333b928d8bcffa26ab19bf018369a835f697585
External References: https://istio.io/latest/news/releases/1.9.x/announcing-1.9.5/
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-29492